๐บ๐ธ
TPI-Abuse
2026-07-28 03:26:04
(1 hour ago)
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 23:25:59.774892 2026] [security2:error] [pid 499538:tid 499538] [client 67.222.30.86:42950] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||twincitytn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "twincitytn.com"] [uri "/wp/wp-json/wp/v2/users"] [unique_id "amghR17XWLz2UU7ONSoZpAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-28 02:45:54
(2 hours ago)
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probin ...
show more
Attacks websites by trying to access known vulnerables of plugins, brute-force of backends or probing of administrative tools
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 01:15:41
(3 hours ago)
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 21:15:37.528875 2026] [security2:error] [pid 1816294:tid 1816294] [client 67.222.30.86:43906] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.webseographics.smogsandiego.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.webseographics.smogsandiego.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amgCuclUfYEacUWwKaT5GgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 00:18:29
(4 hours ago)
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 20:18:22.736413 2026] [security2:error] [pid 1420489:tid 1420489] [client 67.222.30.86:45506] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||blindshine.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "blindshine.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "amf1TmUy4F-_dNzoErqOWQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 22:39:46
(6 hours ago)
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 18:39:42.225820 2026] [security2:error] [pid 870201:tid 870201] [client 67.222.30.86:39926] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.convtek.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.convtek.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amfeLnWOvlGBtIuwIZC1sgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 20:18:46
(8 hours ago)
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 16:18:38.877675 2026] [security2:error] [pid 798106:tid 798106] [client 67.222.30.86:33892] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||impressionsinthread.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "impressionsinthread.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ame9Hp37nk6WUbQd7bToGwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:55:42
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:55:36.712303 2026] [security2:error] [pid 1771775:tid 1771775] [client 67.222.30.86:51280] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||bundrenfarmstn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "bundrenfarmstn.com"] [uri "/index.php/wp-json/wp/v2/users"] [unique_id "amd_eK-Zvf8Sb_IxfOWCAwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-27 15:27:39
(13 hours ago)
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in ...
show more
(mod_security) mod_security (id:225170) triggered by 67.222.30.86 (cp57-ga.privatesystems.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 11:27:35.120825 2026] [security2:error] [pid 2318220:tid 2318333] [client 67.222.30.86:48466] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||jimlawrencesongs.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "jimlawrencesongs.com"] [uri "/wp-json/wp/v2/users"] [unique_id "amd457eiafzc66ZXNB1HbAAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-27 13:25:32
(15 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
tecnicorioja
2026-07-26 22:01:25
(1 day ago)
wp-login attack [26/Jul/2026:21:19:11
Brute-Force
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-26 08:13:56
(1 day ago)
cloudlinux2 fail2ban: 2026-07-26 10:09:40,702 fail2ban.filter [1888]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-26 10:09:40,702 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 49.148.243.117 - 2026-07-26 10:09:40cloudlinux2 fail2ban: 2026-07-26 10:10:02,929 fail2ban.actions [1888]: NOTICE [plesk-modsecurity] Ban 49.148.243.117cloudlinux2 fail2ban: 2026-07-26 10:10:04,001 fail2ban.filter [1888]: INFO [plesk-wordpress] Found 67.222.30.86 - 2026-07-26 10:10:03cloudlinux2 fail2ban: 2026-07-26 10:10:02,639 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 49.148.243.117 - 2026-07-26 10:10:02cloudlinux2 fail2ban: 2026-07-26 10:10:02,937 fail2ban.filter [1888]: INFO [recidive] Found 49.148.243.117 - 2026-07-26 10:10:02cloudlinux2 fail2ban: 2026-07-26 10:10:23,477 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 103.167.233.183 - 2026-07-26 10:10:23cloudlinux2 fail2ban: 2026-07-26 10:11:37,260 fail2ban.filter [1888]: INFO [plesk-modsecurity] Found 103.167.233.183 - 2026-07-26 10:11:37cloudlinux2 fail2ban: 2
show less
Web App Attack
Anonymous
2026-07-25 14:15:33
(2 days ago)
Web attack blocked by Wordfence on mergel.nu (1 hit). Reported by CRMON.
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-25 05:48:57
(2 days ago)
cloudlinux2 fail2ban: 2026-07-25 07:43:43,859 fail2ban.filter [1816]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-25 07:43:43,859 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 106.219.149.246 - 2026-07-25 07:43:43cloudlinux2 fail2ban: 2026-07-25 07:44:27,181 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 158.140.162.209 - 2026-07-25 07:44:27cloudlinux2 fail2ban: 2026-07-25 07:44:48,497 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 158.140.162.209 - 2026-07-25 07:44:48cloudlinux2 fail2ban: 2026-07-25 07:44:48,641 fail2ban.filter [1816]: INFO [recidive] Found 158.140.162.209 - 2026-07-25 07:44:48cloudlinux2 fail2ban: 2026-07-25 07:44:48,639 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Ban 158.140.162.209cloudlinux2 fail2ban: 2026-07-25 07:44:58,236 fail2ban.filter [1816]: INFO [plesk-modsecurity] Found 106.219.149.246 - 2026-07-25 07:44:58cloudlinux2 fail2ban: 2026-07-25 07:44:58,664 fail2ban.actions [1816]: NOTICE [plesk-modsecurity] Ban 106.219.149.246cloudlinux2 fail2ban: 2026-07-25 07:44
show less
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-07-25 04:11:27
(3 days ago)
Wordpress malicious attack:[octaflood]
Web App Attack
๐บ๐ธ
lostswordfish.com
2026-07-24 19:50:04
(3 days ago)
Wordfence waf block on floridaactioncommittee
Web App Attack